Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.
40,434 vulnerabilities found (page 1522 of 1618)
| CVE ID | Plugin / Theme | Severity | CVSS | Description | Fixed In | Source |
|---|---|---|---|---|---|---|
| 413d3ec0-8d04-4bef-9394-f666cfed733e | < 1.2.3.23 |
MEDIUM | 4.3 | The UsersWP – Front-end login form, User Registration, User Profile & Members Directory plugin for WordPress plugin fo… | — | wordfence |
| 411ca76a-6cab-4829-8e8b-5c54697cf8ee | < 10.0.2 |
MEDIUM | 4.3 | The Jetpack – WP Security, Backup, Speed, & Growth plugin for WordPress is vulnerable to unauthorized access of data d… | — | wordfence |
| 4119cfa8-99a3-4d66-a18c-d8dff6916bd2 | MEDIUM | 4.3 | The 多说社会化评论框 plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and… | — | wordfence | |
| 4119178c-9227-4623-a962-e0f103612c75 | MEDIUM | 4.3 | The Ultimate YouTube Video & Shorts Player With Vimeo plugin for WordPress is vulnerable to unauthorized access of data … | — | wordfence | |
| 4115a8d8-4651-41a8-94a7-5ebe8d23ee42 | < 2.0.6 |
MEDIUM | 4.3 | The CM Ad Changer – A simple tool to control and optimize your site's banners plugin for WordPress is vulnerable … | — | wordfence |
| 4112ca9a-39fa-4fe8-a060-9f8f492eb846 | MEDIUM | 4.3 | The Webmaster Tools plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2… | — | wordfence | |
| 40eaeb28-c721-4977-951d-582b7dc2bd12 | MEDIUM | 4.3 | The addfreespace plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, … | — | wordfence | |
| 40e7be75-2336-4702-a98d-8058c26aa017 | < 2.2.8 |
MEDIUM | 4.3 | The Easy Elementor Addons plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on… | — | wordfence |
| 40d6ee3f-43d4-4393-a364-f00b3f3c5d78 | MEDIUM | 4.3 | The Phee's LinkPreview plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including… | — | wordfence | |
| 40cbd3c8-546d-44c6-857f-96913fa8cef8 | MEDIUM | 4.3 | The OpenPix for WooCommerce plugin for WordPress is vulnerable to unauthorized access due to a missing capability check … | — | wordfence | |
| 40cb4d77-ee8d-42ff-9c18-0cd76910edb7 | < 3.5.4 |
MEDIUM | 4.3 | The MyBookTable Bookstore plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and includ… | — | wordfence |
| 40bf51bf-efb2-4504-815b-4681d1078f77 | < 1.1.4 |
MEDIUM | 4.3 | The BEAR for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.1.3.3. This is du… | — | wordfence |
| 40b6f927-7b05-464e-858a-438b7b9ac81c | < 3.7.25 |
MEDIUM | 4.3 | The Hueman theme for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.7.24. Thi… | — | wordfence |
| 409bcd8c-6cd3-4022-a67f-57e901c83d66 | MEDIUM | 4.3 | The WP JobHunt plugin for WordPress, used by the JobCareer theme, is vulnerable to Insecure Direct Object Reference in a… | — | wordfence | |
| 40906dea-6b9e-48ce-9e2b-64d1559cf8e2 | < 1.8.15 |
MEDIUM | 4.3 | The Envira Photo Gallery plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capabi… | — | wordfence |
| 408f0c2a-ef3c-4592-8722-d56afce92e24 | < 2.8.140 |
MEDIUM | 4.3 | The GeoDirectory – WP Business Directory Plugin and Classified Listings Directory plugin for WordPress is vulnerable t… | — | wordfence |
| 40886b66-f6a2-404c-9d0d-5fc3da6a896c | < 2.5.3 |
MEDIUM | 4.3 | The Foxtool All-in-One: Contact chat button, Custom login, Media optimize images plugin for WordPress is vulnerable to C… | — | wordfence |
| 407eb7a7-6243-47f8-8091-86832ae64d64 | < 4.9.0 |
MEDIUM | 4.3 | The Buckaroo Woocommerce Payments Plugin plugin for WordPress is vulnerable to unauthorized access due to a missing capa… | — | wordfence |
| 4077029c-65eb-49f4-91dc-002a7d9cf4c7 | MEDIUM | 4.3 | The StaffList plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function … | — | wordfence | |
| 406f6bd7-f57f-4725-a36f-9846ac04f945 | < 2.0.1 |
MEDIUM | 4.3 | The WP To Do plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.3.… | — | wordfence |
| 40655278-6915-4a76-ac2d-bb161d3cee92 | < 1.8.7.3 |
MEDIUM | 4.3 | The Gallery Plugin for WordPress – Envira Photo Gallery plugin for WordPress is vulnerable to unauthorized modificatio… | — | wordfence |
| 40535215-9f82-4324-8b02-8f3e2ea82940 | < 4.9.7 |
MEDIUM | 4.3 | The WP Maps – Google Maps,OpenStreetMap,Mapbox,Store Locator,Listing,Directory & Filters plugin for WordPress is vulne… | — | wordfence |
| 4049f8fb-ad81-4f09-97b3-39ac6a9275d6 | MEDIUM | 4.3 | The Post Hit Counter plugin for WordPress is vulnerable to unauthorized use of functionality due to a missing capability… | — | wordfence | |
| 40487921-b9eb-4a18-b6f5-194611d2ef82 | MEDIUM | 4.3 | The Easy Cookie Law plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3… | — | wordfence | |
| 4026d57c-47e6-456d-abf1-24e82464bf69 | < 4.9.5 |
MEDIUM | 4.3 | The Advanced Dynamic Pricing for WooCommerce plugin for WordPress is vulnerable to Cross-Site Request Forgery in all ver… | — | wordfence |
EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.
Scan My Website →